Title : Nagios Plugins "redir()" Location Header Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-3394 CVE ID : CVE-2007-5198
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-10-08
Technical Description
A vulnerability has been identified in Nagios Plugins, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the "redir()" [check_http.c] function when processing an overly long "Location:" header, which could be exploited by remote attackers to execute arbitrary code by tricking a user into connecting to a malicious web server.